Galaxy Digital reports that ethical hackers have transferred 52 BTC to an address with an OP_RETURN message stating "claim:cryptorecoverytrust dot com."
By Omkar Godbole, AI Boost|Edited by Shaurya Malwa32 minutes ago2 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on Whitehats move 52 BTC to a recovery trust. (Galaxy)SummaryShow- Ethical hackers have transferred 52.37 Bitcoin linked to the Coldcard wallet breach in July to a new recovery trust address.
- The hack, which resulted in losses exceeding $100 million, exploited weak software randomness to create wallet seeds vulnerable to reconstruction.
- Victims can verify their wallet addresses at cryptorecoverytrust.com to see if their funds were recovered.
According to Galaxy Digital's Head of Research Alex Thorn, ethical hackers, referred to as “whitehat operators,” have moved 52.37 BTC to a newly established recovery trust address following the Coldcard hardware wallet breach that occurred in July.
The Coldcard wallet hack started on July 30, with multiple attack waves leading to estimated losses of over $100 million in Bitcoin
BTC$85,407.70. The attackers took advantage of vulnerabilities that allowed wallets to generate seeds based on a less secure software random number source instead of the hardware's dedicated generator, making them susceptible to being reconstructed by hackers.Coinkite, the manufacturer of Coldcard, has since updated the firmware, but funds exposed by the original insecure seeds remain at risk.
Read More: Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
Thorn noted that some of the Bitcoin moved from victim wallets was not taken by malicious actors but rather by ethical hackers who employ their skills to identify and rectify security vulnerabilities.
These ethical hackers, known as whitehats, collected the funds to safeguard them until they can be returned to their rightful owners.
The recent transfer of 52.37 BTC represents a consolidation of funds from Wave 2 of the exploit, along with three other labeled footprints AA, AU, and AX, sent to an address with an OP_RETURN message indicating "claim:cryptorecoverytrust dot com." This transaction was confirmed in block 967,948.
This amount accounts for approximately 2.8% of the total tracked exploit funds, with around 40% of Wave 2 now identified as whitehat activity. Additionally, 3.0134 BTC with no previous tracking history was also sent to the CRT address in the same transaction, which Thorn suggested may be more whitehat-recovered funds, though this remains unverified.
Victims can check if their funds were among those recovered by visiting cryptorecoverytrust.com and entering their wallet addresses.
